HomeSecurityChile: Government agency attacked by ransomware

Chile: Government agency hit by ransomware attack

Chile's national computer security and incident response team (CSIRT) announced that a ransomware attack has affected the operations and online services of a government agency in the country.

See also: Interworks cloud cyberattack: Remediation on DNS and Acronis services

Chile: Government agency hit by ransomware attack

The attack began on Thursday, August 25, targeting Microsoft and VMware ESXi servers managed by the service.

The hackers stopped all running virtual machines and encrypted their files, adding the “.crypt” filename extension.

See also: Montenegro ransomware attack: Hackers demand $10 million

According to the CSIRT, the malware used in this attack also had functions to steal credentials from web browsers, list removable devices for encryption, and avoid virus detection using execution timeouts.

In typical double blackmail fashion, the attackers offered the Chilean CSIRT a communication channel to negotiate a ransom payment that would prevent being leaked and unlock the encrypted data.

The attacker set a three-day deadline and threatened to sell the stolen data to other cybercriminals on the dark web.

The performance is unclear

The Chilean CSIRT announcement does not name the ransomware group responsible for the attack, nor does it provide sufficient details that would lead to the identification of the malware.

The extension appended to encrypted files offers no clues because it has not been used by many threat actors.

While the little information provided by Chile's CSIRT about the malware's behavior points to the "RedAlert" ransomware (also known as "N13V"), the technical details of an operation running in July 2022 suggest otherwise.

RedAlert ransomware has used the “.crypt” extension in attacks. However, the indicators of compromise (IoCs) in the Chilean CSIRT announcement either link to Conti or return an ambiguous result when fed to automated analysis systems.

Conti has previously been linked to attacks on entire nations, such as the one in Costa Rica in July 2022, which took five days from gaining initial access to stealing and encrypting systems.

Chilean threat analyst Germán Fernández told BleepingComputer that the strain appears to be completely new, and the researchers he spoke to couldn't correlate the malware with anything we know.

See also: Instagram phishing: Users are lured with blue badges

ransomware

Chile's cybersecurity agency recommends that all government entities as well as large private organizations in the country implement the following measures:

  • Use a properly configured firewall and antivirus
  • Update VMware and Microsoft assets
  • Keep backups of your most important data
  • Verify the configuration of anti-spam filters and train employees to recognize malicious emails
  • Implement network segmentation and enforce the principle of least privilege
  • Stay informed about new vulnerabilities that need immediate patching or mitigation

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS